Chainalysis links most of the stolen XRP in $387M Bitget hack to North Korea

Photo: Tima Miroshnichenko / Pexels

Chainalysis links most of the stolen XRP in $387M Bitget hack to North Korea

Blockchain analytics firm says AI tools cut cross-chain tracing time as suspected DPRK thefts pass $1 billion this year

Chainalysis has tied most of the XRP stolen in the Bitget hack to North Korea. That adds another major name to a growing list of firms pointing at Pyongyang.

The heist drained approximately $387.5 million from the exchange’s hot and warm wallets. It is the largest crypto exchange hack reported in 2026.

How the Bitget breach unfolded

The attack hit on September 24, 2026. Bitget detected unauthorized transfers at 18:31 UTC.

The attackers did not steal private keys. They compromised a backend wallet system instead. That access let them spoof transaction data and trick Bitget’s own authorization checks into approving the withdrawals.

The losses spread across several blockchains, mainly Ethereum, XRP Ledger, Zcash, and Tron. Bitget’s cold wallets stayed secure.

The damage estimate also grew after the fact. The figure was first put at $351.6 million before being revised to $387.5 million.

XRP was the single biggest casualty. Roughly 103 million XRP, worth about $157 million, left the exchange.

Advertisement

Following the money across chains

Chainalysis published its findings on October 1, 2026. The report focused heavily on the stolen XRP and on how quickly it moved.

The funds were split into 23 distinct transfers. In the first three hours, XRP made up roughly 40.8% of everything taken.

Much of that XRP was then pushed through cross-chain liquidity protocols such as THORChain and converted into Bitcoin.

Chainalysis said its in-house AI tools helped speed up that process considerably. According to the firm, manual bridge analysis that once took more than 20 hours dropped to under 10 minutes.

Only around 0.2% of the stolen funds have been frozen by issuers or protocols so far.

The North Korea attribution

Bitget did not wait for outside analysts to name a suspect. CEO Gracy Chen quickly flagged a connection to North Korean state-linked groups.

Chen pointed to matching IP addresses and familiar on-chain activity patterns.

Other analytics firms backed her up. TRM Labs and Elliptic both linked the breach to earlier incidents involving DPRK hackers following their own investigations.

The Bitget theft also pushes a grim tally higher. Suspected North Korean digital asset thefts have totaled over $1 billion in 2026 alone.

Bitget’s backstop

For customers, the most important number may be $464 million. That is roughly the value of Bitget’s User Protection Fund, which the exchange says sits above that level.

Bitget has pledged the fund will fully cover the loss. The exchange says customer balances will not be affected.

With almost none of the stolen assets frozen, the money spent replenishing users is money the exchange is unlikely to see again.

What this means for exchanges and users

The most uncomfortable detail here is that no private keys were stolen. This attack sidestepped key security entirely. By corrupting the systems that decide whether a withdrawal looks legitimate, the hackers made the exchange approve its own robbery.

Chainalysis’s claim that AI cut bridge tracing from over 20 hours to under 10 minutes hints at an arms race. Attackers lean on instant swaps and cross-chain hops to scatter funds, while analytics firms automate the chase. A freeze rate of about 0.2% suggests faster tracing has not yet translated into recovered money.

Disclosure: This article was edited by John Chen. For more information on how we create and review content, see our Editorial Policy.
Chainalysis links most of the stolen XRP in $387M Bitget hack to North Korea
Chainalysis links most of the stolen XRP in $387M Bitget hack to North Korea

Blockchain analytics firm says AI tools cut cross-chain tracing time as suspected DPRK thefts pass $1 billion this year

Share

Add us on Google

Photo: Tima Miroshnichenko / Pexels

Chainalysis has tied most of the XRP stolen in the Bitget hack to North Korea. That adds another major name to a growing list of firms pointing at Pyongyang.

The heist drained approximately $387.5 million from the exchange’s hot and warm wallets. It is the largest crypto exchange hack reported in 2026.

How the Bitget breach unfolded

The attack hit on September 24, 2026. Bitget detected unauthorized transfers at 18:31 UTC.

The attackers did not steal private keys. They compromised a backend wallet system instead. That access let them spoof transaction data and trick Bitget’s own authorization checks into approving the withdrawals.

The losses spread across several blockchains, mainly Ethereum, XRP Ledger, Zcash, and Tron. Bitget’s cold wallets stayed secure.

The damage estimate also grew after the fact. The figure was first put at $351.6 million before being revised to $387.5 million.

XRP was the single biggest casualty. Roughly 103 million XRP, worth about $157 million, left the exchange.

Advertisement

Following the money across chains

Chainalysis published its findings on October 1, 2026. The report focused heavily on the stolen XRP and on how quickly it moved.

The funds were split into 23 distinct transfers. In the first three hours, XRP made up roughly 40.8% of everything taken.

Much of that XRP was then pushed through cross-chain liquidity protocols such as THORChain and converted into Bitcoin.

Chainalysis said its in-house AI tools helped speed up that process considerably. According to the firm, manual bridge analysis that once took more than 20 hours dropped to under 10 minutes.

Only around 0.2% of the stolen funds have been frozen by issuers or protocols so far.

The North Korea attribution

Bitget did not wait for outside analysts to name a suspect. CEO Gracy Chen quickly flagged a connection to North Korean state-linked groups.

Chen pointed to matching IP addresses and familiar on-chain activity patterns.

Other analytics firms backed her up. TRM Labs and Elliptic both linked the breach to earlier incidents involving DPRK hackers following their own investigations.

The Bitget theft also pushes a grim tally higher. Suspected North Korean digital asset thefts have totaled over $1 billion in 2026 alone.

Bitget’s backstop

For customers, the most important number may be $464 million. That is roughly the value of Bitget’s User Protection Fund, which the exchange says sits above that level.

Bitget has pledged the fund will fully cover the loss. The exchange says customer balances will not be affected.

With almost none of the stolen assets frozen, the money spent replenishing users is money the exchange is unlikely to see again.

What this means for exchanges and users

The most uncomfortable detail here is that no private keys were stolen. This attack sidestepped key security entirely. By corrupting the systems that decide whether a withdrawal looks legitimate, the hackers made the exchange approve its own robbery.

Chainalysis’s claim that AI cut bridge tracing from over 20 hours to under 10 minutes hints at an arms race. Attackers lean on instant swaps and cross-chain hops to scatter funds, while analytics firms automate the chase. A freeze rate of about 0.2% suggests faster tracing has not yet translated into recovered money.

Disclosure: This article was edited by John Chen. For more information on how we create and review content, see our Editorial Policy.